Technical Program Manager – Cyber / Data Security

Morgan StanleyNew York, NY
$195,000 - $275,000Onsite

About The Position

Morgan Stanley is seeking a Data Security Program Manager to join their Strategic Programs Execution (SPE) team, which is part of the Cyber, Data, Risk and Resilience (CDRR) Super Department. This role is responsible for leading complex data security programs aimed at reducing firmwide risk, strengthening control execution, and advancing the Firm's Data Security Strategy. The individual will manage cross-divisional delivery across Technology, Cyber, Business, Risk, and Control stakeholders, with accountability for planning, governance, milestone execution, risk and issue management, metrics reporting, and executive communication. The candidate should possess strong program management discipline, data security domain awareness, and the ability to translate technical control delivery into risk-reducing outcomes for senior leadership. The initial assignment involves driving the execution of data security risk reduction initiatives within the Data Security Risk Execution (DSRE) portfolio, supporting governance through the Data Security Execution Governance Committee (DSEGC), and ensuring delivery aligns with the Firm's Data Security Strategy, applicable policy requirements, and risk appetite. The program scope includes oversight of various data security capabilities such as Data Leakage Prevention, Data Discovery, Data Masking, Secure Logging, Encryption at Rest, Encryption in Transit, Post-Quantum Cryptography readiness, API security, identity and access management, anomalous behavior detection, incident management, external website controls, network security, vendor risk management, and third-party data protection. This is a hands-on leadership role requiring close partnership with control owners, delivery leads, Business Unit sponsors, 1LOD/2LOD/3LOD stakeholders, and senior governance forums to drive transparent execution, timely escalation, and sustainable transition of mature capabilities to business-as-usual monitoring. The program is currently in its execution phase, with the detailed approach and plan for BAU transition yet to be agreed.

Requirements

  • At least 10 years demonstrable project management experience
  • Demonstrable track record of operating and delivering at program manager level - 3 years minimum
  • Demonstrable experience leading change in a data security, cyber risk, technology controls, compliance, or regulatory environment.
  • Experience producing executive-ready program reporting, including milestone plans, RAID logs, KPI/KRI dashboards, OpenPages Issue and Action Plan status, and governance materials for senior committees.
  • Experienced of leading projects/programs using waterfall and agile methodologies

Nice To Haves

  • Strong knowledge of data security, cyber controls, risk management, and technology governance, with familiarity across DLP, data discovery, encryption, identity and access management, incident response, API security, vendor risk, and third-party data protection.
  • Previous experience on data security, cyber risk, control remediation, regulatory, or assessment programs strongly preferred.
  • Leading and driving delivery teams
  • Transitioning into BAU, including change management
  • Managing using a risk-based data security program approach, including alignment of milestones, evidence, metrics, issues, and action plans to measurable risk reduction.
  • Defining and tracking data security benefits, including improved control coverage, reduced residual risk, stronger governance, increased transparency, and sustainable BAU monitoring.
  • Effective interpersonal and communication skills
  • Ability to create a sense of community amongst the disparate members of the project teams
  • A strong knowledge of techniques for planning, monitoring, and controlling programs

Responsibilities

  • Lead data security risk reduction execution: coordinate delivery across DSRE workstreams, ensuring milestones, action plans, dependencies, and risk-reducing outcomes are clearly defined, tracked, and achieved.
  • Manage governance and executive reporting: prepare high-quality updates for DSEGC and related governance forums, including program status, risks, issues, decisions, metrics, and path-to-green plans.
  • Drive milestone-based delivery plans and BAU transition: establish integrated plans that support control implementation, adoption, operational readiness, evidence capture, and sustainable metrics-based monitoring.
  • Manage cross-program dependencies: partner with related technology, cyber, risk, policy, and business programs to align scope, delivery sequencing, control requirements.
  • Strengthen data security metrics and risk reporting: partner with metrics owners to define KPIs, KRIs, thresholds, trends, and executive narratives that demonstrate measurable control effectiveness and risk reduction.
  • Support emerging technology and AI security integration: identify opportunities to improve data protection governance for AI-enabled use cases, external websites, APIs, SaaS platforms, and other evolving data movement channels.
  • Develop program artifacts: maintain charters, roadmaps, stakeholder maps, RAID logs, action trackers, decision logs, program briefs, meeting materials, and executive-level communications.
  • Translate data into actionable insights for senior audiences: analyze program status, delivery trends, control metrics, risks, dependencies.

Benefits

  • Ample opportunity to move about the business for those who show passion and grit in their work.
  • Attractive and comprehensive employee benefits and perks in the industry.
  • Support for employees and their families at every point along their work-life journey.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service